WP Custom Admin Interface <= 7.42 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WP Custom Admin Interface plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 6.4
- Affected:
- up to 7.42
- Fixed in:
- 7.43
- Disclosed:
- Mar 20, 2026
CVE-2026-32521 on NVD →
WP Custom Admin Interface [wp-custom-admin-interface] <= 7.41 (unfixed)
unknown
[en] Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41.
- Affected:
- up to 7.41
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-25011 on NVD →
Custom Admin Interface <= 7.41 - Missing Authorization
medium
The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.41. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 7.41
- Fixed in:
- 7.42
- Disclosed:
- Jan 25, 2026
CVE-2026-25011 on NVD →
Custom Admin Interface <= 7.40 - Missing Authorization
medium
The Custom Admin Interface plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.40. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 7.40
- Fixed in:
- 7.41
- Disclosed:
- Dec 31, 2025
CVE-2025-63038 on NVD →
WP Custom Admin Interface [wp-custom-admin-interface] <= 7.40 (unfixed)
unknown
[en] Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.40.
- Affected:
- up to 7.40
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-63038 on NVD →
WP Custom Admin Interface [wp-custom-admin-interface] < 7.33
unknown
[en] Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.32.
- Affected:
- up to 7.33
- Fixed in:
- 7.33
- Disclosed:
- Jan 2, 2025
CVE-2023-44988 on NVD →
WP Custom Admin Interface [wp-custom-admin-interface] < 7.32
unknown
[en] Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.31.
- Affected:
- up to 7.32
- Fixed in:
- 7.32
- Disclosed:
- Dec 9, 2024
CVE-2023-47763 on NVD →
WP Custom Admin Interface <= 7.31 - Missing Authorization via wpcai_pro_notice_disable
medium
The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missing capability check on the wpcai_pro_notice_disable function in versions up to, and including, 7.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismis...
- CVSS:
- 4.3
- Affected:
- up to 7.31
- Fixed in:
- 7.32
- Disclosed:
- Nov 13, 2023
CVE-2023-47763 on NVD →
WP Custom Admin Interface <= 7.32 - Missing Authorization to Transients Deletion
medium
The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_custom_admin_interface_delete_transients function in versions up to, and including, 7.32. This makes it possible for authenticated attackers, with subscriber-level privileges...
- CVSS:
- 4.3
- Affected:
- up to 7.33
- Fixed in:
- 7.33
- Disclosed:
- Sep 29, 2023
CVE-2023-44988 on NVD →
WP Custom Admin Interface <= 7.32 - Cross-Site Request Forgery to Transients Deletion
medium
The WP Custom Admin Interface plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.32. This is due to missing or incorrect nonce validation on the wp_custom_admin_interface_delete_transients function. This makes it possible for unauthenticated attackers to delete plugin t...
- CVSS:
- 4.3
- Affected:
- up to 7.33
- Fixed in:
- 7.33
- Disclosed:
- Sep 29, 2023
WP Custom Admin Interface [wp-custom-admin-interface] < 7.33
unknown
The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_custom_admin_interface_delete_transients function in versions up to, and including, 7.32. This makes it possible for authenticated attackers, with subscriber-level privileges...
- Affected:
- up to 7.33
- Fixed in:
- 7.33
- Disclosed:
- Sep 29, 2023
WP Custom Admin Interface [wp-custom-admin-interface] < 7.33
unknown
The WP Custom Admin Interface plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.32. This is due to missing or incorrect nonce validation on the wp_custom_admin_interface_delete_transients function. This makes it possible for unauthenticated attackers to delete plugin t...
- Affected:
- up to 7.33
- Fixed in:
- 7.33
- Disclosed:
- Sep 29, 2023
WP Custom Admin Interface [wp-custom-admin-interface] < 7.29
unknown
[en] The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- Affected:
- up to 7.29
- Fixed in:
- 7.29
- Disclosed:
- Jan 9, 2023
CVE-2022-4043 on NVD →
WP Custom Admin Interface <= 7.28 - Authenticated (Administrator+) PHP Object Injection
high
The WP Custom Admin Interface plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.28, via deserialization of untrusted input in the northernbeacheswebsites_information and wp_custom_admin_interface_import_settings functions. This allows administrator-level attackers to inject...
- CVSS:
- 7.2
- Affected:
- up to 7.28
- Fixed in:
- 7.29
- Disclosed:
- Dec 13, 2022
CVE-2022-4043 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database